PT-2023-15530 · Secvisogram · Csaf-Validator-Service

Damian Pfammatter

·

Published

2023-03-27

·

Updated

2024-02-15

·

CVE-2022-47925

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Secvisogram csaf-validator-service versions prior to 0.1.0
Description The issue is related to insufficient input validation of requests by an unauthenticated remote user, which might lead to a partial Denial of Service (DoS) of the service. Specifically, the validate JSON endpoint processes tests with unexpected names. This affects only the request of the attacker.
Recommendations For versions prior to 0.1.0, update to version 0.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the validate JSON endpoint to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-47925

Affected Products

Csaf-Validator-Service